One container replaces the Calibre and Calibre-Web pairing
Calibre-Web Automated starts with Calibre-Web's browser interface and adds the library jobs that often send self-hosters back to desktop Calibre. It watches an ingest folder, imports books, converts formats, applies metadata and covers, scans duplicates, backs up processed originals, and sends files to readers. Kobo and KOReader sync sit beside OPDS and browser reading. The appeal is simple: one service owns the tedious path from a new file to a readable library entry.
That convenience reaches deep into the collection. The measured checkout contained 1,197 files, about 162,511 lines of source, and occupied 154.1 MB before its 62 Python packages were installed. CWA can rename book folders, write metadata into ebook files, remove duplicates, and replace converted formats. Its ingest mount is a queue, not storage: the README says every file there is removed after processing. Start with copies and keep the library backup outside all 3 mounted directories.
Automation covers 27 ingest formats and can modify the originals
The README lists automatic ingest for 27 formats and conversion across 28 file types, with EPUB as the default target. Cover and metadata changes made in the web interface can be written back into ebook files. An EPUB fixer repairs several structures that can trip up Send to Kindle, while a conversion tool can retain originals under /config/processed_books. Smart duplicate detection, scheduled scans, Magic Shelves, and automatic sending extend the same pipeline.
A wide pipeline creates more ways for a success label to be wrong. Open issue 1551 describes Convert Library reporting every book as converted after an ingest had removed its temporary directory, even though no new formats appeared. The report also says subprocess exit codes fell through to success messages. Pull request 1552 proposes creating the directory and surfacing command failures, but it was still open when checked. Until that lands in a release you verify, compare the library formats before and after bulk work.
What happened when we ran it
Our sandbox installed commit 9805ac0 in 26 seconds, adding 62 packages and using 93 MB on disk. The build completed in 3 seconds. The test command then exited with code 1 after 22 seconds. Pytest reported 90 passed, 26 failed, 90 skipped, and 46 collection or setup errors of 162. Pip-audit found 0 known vulnerabilities in the installed Python environment.
The log tail repeatedly showed ModuleNotFoundError for cps.internal_api, with Python saying cps was not a package. Another duplicate-handling test failed because cps.duplicates had no _timestamp_or_default attribute. Those messages establish what broke in our fresh Debian run; they do not establish why. The checkout had a tests directory, Dockerfile, Compose file, and 6 CI workflow files, which makes the local failure harder to dismiss as a repository with no test machinery.
A passing build and clean dependency audit still count. They show that the 93 MB installed environment resolved and that the packaging step worked. They do not cancel 26 failed cases or the 46 errors that stopped other cases from setting up. Since several failures named duplicate scanning and queue behavior, test that feature on a disposable library before enabling automatic resolution against real books.
Docker setup depends on 3 separate writable mounts
The recommended Compose file maps /config, /cwa-book-ingest, and /calibre-library; the README warns against nesting them. PUID and PGID must match the host owner. The web interface defaults to port 8083, and first login uses admin with admin123. Change that password immediately. New users can bind an empty library directory, while migrating Calibre-Web users should stop the old service and copy its config before mounting it here.
Permissions deserve a trial of their own. Open issue 1472 consolidates reports where uploads or ingest left files with ownership that prevented later metadata edits, deletion, or directory moves. It names both Docker and bare-metal installs on version 4.0.6. Release v4.0.7 changed the ingest service to run as the abc user and includes an ownership upgrade note, but the issue remained open and was updated after that release. Check ownership after one upload and one watched-folder import.
NAS mode trades SQLite WAL and file events for polling
Local disks use SQLite write-ahead logging and inotify. NFS and SMB users set NETWORK_SHARE_MODE=true, which disables WAL for metadata.db and app.db, skips recursive ownership changes, and changes ingest and metadata watchers to polling. Docker Desktop may choose polling automatically because events from Windows or macOS mounts can be unreliable. The trade is a few seconds of detection delay and more I/O, according to the README.
Reverse proxies bring another exact setting. CWA trusts 1 proxy by default through Werkzeug's ProxyFix. A chain such as Cloudflare Tunnel followed by nginx needs TRUSTED_PROXY_COUNT=2; the wrong count can make session protection see changing client addresses and force logins again. OAuth and OIDC can be configured for external identity, while Hardcover metadata, email delivery, Kobo, and KOReader each add credentials or device setup. The 3-second build measured none of those integrations.
Version 4.0.7 fixes access control while open bugs remain
GitHub recorded a push on September 28, 2026, and release v4.0.7 arrived one day earlier. The release fixed Kobo token access, unauthenticated service pages, externally reachable internal endpoints, and guest access to a single-book EPUB fixer. That is a reason to update, especially for an internet-facing library. It also shows why pinning and reading release notes matter for a server that handles user accounts and file-changing jobs.
The repository had 6,331 stars and 442 combined issues and pull requests when fetched. Same-day commits and the new release show active maintenance; the large queue and our failed suite show active risk too. CWA can remove several awkward services from a home library, but its automation has authority over the files you care about. Give it a copied shelf first. Promote it only after ingest, conversion, backup, restore, and reader sync behave on your storage.

